HomeKnowledge CenterAuditing Processes: The Document or the Reality?

Auditing Processes: The Document or the Reality?

Most audits review the document and ignore the shop floor. This article follows an auditor named Majed and an employee named Dana to show how to move from auditing files to auditing reality.

08 Jun 2026RAISO Experts Team

Auditing Processes: The Document or the Reality?

The audit session ends and everything looks fine. Files are in order, forms signed, procedures up to date, and the report shows a high compliance rate. The team applauds and the report goes up to senior management. At the same moment, on the ground floor of the same building, a customer calls for the third time this week because his request has not been handled, an employee skips a step in the procedure because she does not know how to activate it, and colleagues swap customer details over an informal messaging app because the official system is slow.

This article turns on a single question: do we review the document, or do we understand the reality? We follow one case from start to finish: Majed the auditor, Dana the employee, and the process that links them. You will come away with the difference between work as imagined and work as done, an understanding of why traditional audit cannot see the gap, the RAISO “process visit” model, and four stages that take you from the file to the floor and on to a decision, with a short exercise in every section to apply to an audit in your own organisation.

Majed leaves reassured

“We follow one case: Majed, an internal auditor in a service organisation, auditing the supplier payment process. In each section we see what changes in how he audits, and at the end we set his old audit beside the new one.”

— What will you take from this article?

Majed is an internal auditor. He was asked to audit the supplier payment process. He spent two days in a meeting room with the process file: the approved version was current, the amendment log complete, and a sample of fifty transactions had all passed through the six required steps, signatures in place. He closed his report with a compliance rate higher than his department usually celebrates.

A week later a supplier came to the organisation angry: his payment was three weeks overdue though “everything was in order”. When they asked Dana, the employee responsible for step four, she said simply: “Step four in the system hangs on large amounts, so I email the file to a colleague in accounting and ask her to approve it by hand, and I enter the signature into the system later.”

This workaround appears in no document. In the fifty transactions the signature was present, and nobody asked when it was entered or how.

“Majed made no mistake in any step of his method, and yet he saw none of what was actually happening.”

“Majed, Dana and the numbers in this article are composed for illustration only and do not refer to any particular organisation.”

— A hypothetical case

Look back at what happened and reflect. Majed did what an auditor is asked to do: he verified that the procedure exists, that the documents are complete and the signatures present. Dana did what any clever employee does: she found a way to get the work done despite a system fault. Between the two lies a gap that was in no file.

What did the organisation lose in this story?

  • Knowledge. It thought its process worked as written, and it works another way it does not know about.
  • Security. A signature entered later outside the system is a hole in control, and nobody sees it.
  • Trust. When the supplier complained, neither the auditor nor management could explain the delay.

“Five minutes, now: recall the last audit you went through or ran. Did it reveal anything you did not know about how you actually work? Write the answer honestly.”

— Try it now

The organised illusion: documents complete, truth absent

Majed’s organisation fell into a silent trap that many fall into: an audit that reviews documents and ignores reality. When the aim becomes proving compliance rather than understanding performance, audit turns into a formal ritual that produces reassuring reports which do not necessarily reflect what is going on. The report says all is well, the floor says otherwise, and between them lies a grey area that management does not see and its indicators do not measure.

This is what we call the organised illusion: an organisation that looks perfectly disciplined on paper while its real operations run on a different logic. The danger is not that operational problems exist; that is normal in any system. The danger is that complete documents give leadership false confidence that those problems are absent. It is the most dangerous illusion because it comes wrapped in evidence, signatures and numbers.

And when audit cannot see this gap, it does not merely fail at its task. It helps, without knowing, to entrench and beautify it. Majed’s report did not discover Dana’s workaround; it made it harder to discover by stamping it “sound”.

Where the case stands now: Majed reread his old report and noticed that it did not contain a single sentence describing how the process really works. It was a report about the document, not about the work.

“Open the report of your last audit and count how many sentences describe what the auditor saw on the floor, and how many describe what he found in files.”

— Try it now

Audit as ritual: how did it lose its soul?

Audit began as a tool of control and accountability. Its aim was clear: to verify that work proceeds as planned and that resources are used as intended. But something drifted along the way. Documentation mechanisms swelled, compliance requirements grew complicated, and audit turned from a means of understanding reality into an end in itself.

At the heart of this shift lies a subtle displacement in the question. The simpler “is this procedure documented?” took the place of the essential “does this procedure work?”. The difference looks verbal, but it changed the nature of audit entirely. Instead of a journey of discovery to understand how the organisation works, it became a periodic ritual that teams perform to prove compliance and avoid accountability. And when audit becomes ritual, it keeps the shell and loses the soul.

In many organisations an audit counts as successful if it finishes on time, its files are complete and its report appears on schedule. But few ask the questions that reveal its real value:

  • Did this audit reveal something we did not know about our processes?
  • Did it lead to an operational decision different from the one we would have taken?
  • Did it change anything in the way we actually work?
  • Or was it merely a costly reaffirmation of what we know, or think we know?
The four value questions: what did your audit add?
#QuestionYesPartlyNo
1Did the audit reveal something we did not know about our processes?
2Did it lead to an operational decision different from our default?
3Did it change anything in the way we actually work?
4Was it more than a costly reaffirmation of what we know?

Answer for your last audit. Four “no” answers mean a ritual audit.

When the answer is “no”, audit becomes an administrative burden that consumes time and resources without producing knowledge. It keeps the form and loses the substance, and turns from a lever for improvement into a recurring cost.

Where the case stands now: Majed asked himself the four questions about his payment audit, and answered “no” four times. That was not a verdict on him. He was playing the role the audit system was designed for. But he decided to try another role.

“Write the four questions on a sheet and answer them for the last three audits in your organisation. How many “no” answers did you get?”

— Try it now

The unseen gap: work as imagined and work as done

Erik Hollnagel, a researcher in resilience engineering and complex systems, offered a distinction that helps us understand what happened to Majed. In every real organisation there are two levels of work that never coincide.

  • Work as imagined: what documents, procedures and policies describe. A simplified, logical picture of how work is done in ideal conditions, where every resource is available and no exceptions arise.
  • Work as done: what actually happens in the work setting, where people deal with time pressure, ambiguous information, incompatible systems and exceptions that procedures did not cover.

The gap between the two levels is not evidence of negligence or disobedience. It is a natural and inevitable phenomenon in any complex human system. Dana is an example. She did not skip step four to evade it, but because the system hangs on large amounts and the supplier is waiting. Very often these small adjustments are precisely what keeps processes running despite flaws in the official design.

“The real problem is not that a gap exists between document and reality, but that it is absent from the radar of traditional audit.”

Work as imagined and work as done - Two levels that never coincide. The gap between them is natural.
Dana’s example is a hypothetical case

When we cannot see the gap we do not understand the processes. And when we do not understand the processes, improvement initiatives rest on wrong assumptions. We redesign a procedure that works, ignore one that stumbles, and train staff in what they already know, while the real problem stays in a place we never looked. The invisible gap is not just a blind spot; it is where most silent operational risks take shape.

Where the case stands now: Majed understood that Dana did not break the procedure; she patched it. And that the right question is not “who broke it?” but “why did the workaround become easier than the official step?”

“Pick a step in a procedure you know and note: how does the document say it is carried out? How do you think it is actually carried out? Then ask the person who does it.”

— Try it now

Why does traditional audit fail to reach the truth?

The failure is not due to a lack of good intentions but to a flaw in the logic on which it rests. There are structural reasons that make document-based audit unable, by its nature and not through any shortcoming, to see reality.

  1. Confusing existence with effectiveness

    When Majed verifies that the procedure exists, he proves one fact only: that someone wrote it once. He does not answer the real question: does it produce the required result?

  2. Near-total reliance on paper evidence

    The document is a representation of reality, not reality itself. When an auditor builds conclusions on the representation, he assesses the picture of the thing, not the thing.

  3. No direct observation

    The traditional auditor rarely goes down to the work setting. That is an implicit decision that truth lies in the file, not on the floor.

  4. Defensive dynamics

    When an employee learns the auditor is coming, her behaviour changes, not because she is dishonest but because human nature pushes us to show our best when watched. What the auditor sees is a polished version, not daily work.

  5. Producing comfort instead of knowledge

    A good report soothes senior management, but that comfort can itself be the danger if it hides latent problems and dulls vigilance.

Why document audit cannot see reality - Five structural reasons, one outcome.

Together these reasons produce a knowledge gap between what audit measures and what the manager needs. The auditor measures how complete, current and signed a document is. The manager needs to know whether the process works, where it stumbles and why. The wider this gap grows, the more audit turns from a source of insight into a source of false comfort.

Where the case stands now: Majed went back to his old method and found all five reasons in it. He had not gone to the floor, he had announced his visit two weeks ahead, he had measured completeness of the file, and then written a report that soothed everyone.

“Tick each of the five reasons that applies to the last audit in your organisation. Which is most present?”

— Try it now

Compliance as a shield, and standards that shift

Sidney Dekker, a researcher in safety science and complex systems, developed a disturbing idea: that formal compliance does not protect an organisation from error and may make it more exposed to it. As compliance rises, a sense of control arises that numbs vigilance. Leadership is reassured because reports are positive, and teams focus on compliance indicators rather than on understanding processes.

In that situation latent risks pile up quietly, hidden behind high rates, until they erupt at a moment nobody expects. Dekker describes this as the brittleness of well-secured systems: formal safety gives a false sense of immunity that hinders seeing latent faults. The painful irony is that the high rate itself becomes a veil. The better the numbers look, the less the motive to look beneath the surface.

“Do our compliance rates reflect our real operational maturity, or our ability to fill in documents?”

Nor is this a lone view. When ISO 9001 appeared in its 2015 edition it carried a shift that was not read deeply enough in many organisations. Earlier editions put strong weight on documentation: prove you have a written procedure. The 2015 edition moved to another question: prove this procedure works and its results are achieved. This move from “the document exists” to “the process is effective” is not a technical detail but an open admission by the international standards body that organisations spent decades writing procedures without checking that they work.

This philosophy meets the ISO 19011 guidance on auditing, which stresses an evidence-based approach and understanding the process in its context rather than merely matching forms. When the logic of ISO 9001:2015 on effectiveness joins the logic of ISO 19011 on real evidence, the standards-based case for moving from auditing the document to auditing reality is complete. A reality-based audit is not a departure from the standards but a faithful application of their modern spirit.

Where the case stands now: Majed no longer rejoices in a high compliance rate; he asks what the rate is hiding. And instead of arguing with the standard he reread it and found it asks exactly what he is moving towards: to prove the procedure works, not that it is written.

“Ask your manager: if our next audit showed a hundred per cent compliance, what would we do with it? Would we know what it does not capture?”

— Try it now

The floor is the truth: the “process visit” model

RAISO developed an operational concept it calls the “process visit”, resting on an idea that is simple and deep in effect: operational truth is not read in the document but seen on the floor. The concept draws on the logic of Gemba in operational excellence, going to the real place where work is done, and turns it into an organised audit practice.

Traditional audit and the process visit - The visit starts from the opposite assumption: the procedure may be the problem.

A process visit is not an inspection tour or direct surveillance of staff. It is an organised journey of discovery in which the auditor goes to the work setting and observes how processes are carried out in their real context, with their tools, pressures and constraints. Its aim is not to catch violations but to understand how work actually pulses beneath the organisational skin.

The visit moves in two complementary motions. The first is silent observation: the auditor sits beside the employee and watches how she performs her tasks without intervening or directing, capturing the actual sequence of steps and the exceptions that appear in no file. The second is exploratory dialogue, with open questions meant to understand the employee’s logic, not to hold her to account.

Questions that work for opening the dialogue:

  • Why do you prefer this way to what is written in the procedure?
  • What happens when you follow the official step to the letter?
  • What challenges does your work face that the procedure knows nothing about?
  • When do you turn to a workaround, and why?

The visit begins from an assumption opposite to that of traditional audit: when a deviation from the procedure occurs, the problem is not necessarily in the employee but perhaps in the procedure itself. This reversal of viewpoint is what makes the concept truly transformative. The employee changes from a “potential suspect” into a “source of knowledge”, and the deviation from a “violation” into a “signal” worth understanding.

Where the case stands now: Majed asked Dana if he could sit beside her for two hours while she handled the week’s transactions, with no file and no pen. He saw the system hang on a large transaction, saw her email the file to her colleague, then return to the system to enter the signature. When he asked her why, she explained everything with relief, because for the first time she felt someone wanted to understand her rather than to catch her.

“Arrange a one-hour visit to a process you know well. Sit beside a real performer and do not bring the document. Write only what you see, and compare it with the document afterwards.”

— Try it now
The reality-based audit model: four stages - From the floor to the decision, not from the file to the archive.

The reality-based audit model: four stages from floor to decision

Reality-based audit is not a philosophical idea hanging in the air. It is an operating model of four successive stages that moves the audit function from reviewing documents to discovering truth.

  1. Field observation

    Before opening any file the auditor goes to the work setting and observes with method: the actual sequence of steps, the timing of each stage, how the employee handles exceptions. The floor is the first source of truth, and the document comes later for comparison, not as the starting point.

  2. Gap analysis

    The auditor compares what he saw with what is written. The question is not “who broke the procedure?” but “what is the nature of this difference and what explains it?” The gap may point to an outdated procedure, an unenabled work setting, or a real-world complexity the official design overlooked.

  3. Operational interpretation

    Raw observations turn into understanding. The auditor here is not an investigator hunting a culprit but an analyst grasping the logic of the system: what forces push staff towards this behaviour? What makes the deviation a rational choice from the performer’s side? This stage is the cognitive heart of the model.

  4. Linking outputs to improvement

    The end goal is not a report but a decision. Each observation is tied to an operational initiative: redesigning the procedure, developing the work setting, or enabling the team. The cycle turns from a line that ends in the archive into a loop that ends in improvement and returns to measure its effect.

Where the case stands now: Majed wrote his field notes before opening the file, then compared them with the procedure and found three gaps. At interpretation it became clear that everyone had known about the system fault on large amounts for months and nobody had reported it formally, because reporting needs a form and nobody knows who receives it. And that the later signature is a real hole that must be closed, not by reprimanding Dana but by fixing the system.

“Take your notes from the visit exercise and arrange them in three columns: what I saw, what the document says, and what might explain the difference. Put no one’s name in any column.”

— Try it now
Three paths from gap to value
#PathWhen we choose itIn Majed’s case
1Procedure redesignThe procedure is unrealistic, outdated or complexFault-reporting step: redesigned
2Team enablementProcedure is sound, team lacks a tool or authoritySystem hang on large amounts: technical fix
3Exception managementRare cases the procedure never coveredLarge amounts: documented manual approval path

The nature of the gap sets the path. This is how Majed’s gaps spread.

From report to change: three paths to value

One of the most embarrassing questions for any audit team is: what was the last operational decision that changed because of an audit report? In most organisations the answer is embarrassing or absent. That does not mean teams are not working, but that their outputs were not designed to produce decisions, only reports. The report answers “are we compliant?”; the decision answers the more important question: “how do we improve?”

Reality-based audit directs its outputs into three paths, and the path is set by the nature of the gap found.

  1. Procedure redesign path

    When the procedure itself is unrealistic, outdated or needlessly complex, the answer is not to force people onto it but to redesign it to fit reality.

  2. Team enablement path

    When the procedure is sound but the team lacks tools, training or authority, the answer lies in closing the capability gap, not in changing the design.

  3. Exception management path

    When deviations occur in rare cases the procedure never covered, the answer lies in building a clear mechanism for handling the exception rather than denying it.

In Majed’s case the gaps spread across all three paths. The system fault on large amounts needed a technical fix that enables the team. The large amounts themselves were an exception the procedure did not cover, so they needed a documented path for manual approval with immediate recording inside the system. And the fault-reporting step was vague, so it was redesigned and it became known who receives the report.

The essential difference is that reality-based audit does not end its cycle with a report that is archived, but with an initiative that is carried out. That alone turns audit from an administrative cost into an investment in performance. And when every audit becomes a door to improvement, the organisation’s whole relationship with it changes: from something teams fear to something they await, because they know it will make their work easier and smarter.

Where the case stands now: Six weeks later Majed finished his new report, and those at the meeting where he presented it came from finance and IT. Finance asked to amend the procedure, IT promised to fix the fault, and Dana became the one introducing colleagues to the new solution. And for the first time Majed was asked in the meeting: “When will you come back to measure the effect?”

“Take one gap from your notes and decide its path: design, enablement or exception. Then write one decision, its owner and its date.”

— Try it now

The organisation that understands itself

In the end effective audit is a cognitive practice before it is an administrative one. The most mature organisations are not those with the greatest number of documented procedures but those with the deepest grasp of how these procedures work in reality. Operational maturity is not measured by the size of the document library but by leadership’s ability to answer a simple question precisely: how does our team actually get its work done?

The organisation that answers by turning to documents alone lives in its picture of itself. The one that answers from deep understanding of the floor lives in its truth. The difference between them is not one of managerial elegance but of the ability to survive and develop: whoever knows himself honestly can improve, and whoever lives in his image of himself repeats his errors without knowing. And an uncomfortable truth is far cheaper than a costly surprise.

In the context of Saudi Vision 2030 and the high standards of quality and efficiency it sets across the public and private sectors, reality-based audit becomes a necessity rather than a methodological luxury. Organisations aspiring to world-class operational excellence cannot build their transformation on an organised illusion.

Where the case stands now: Majed changed the definition of success in his annual plan. It is no longer “the number of audits completed” but “the number of operational decisions that changed because of them”. The names and numbers here are hypothetical, for illustration, but the shift in the question is real.

“Closing exercise: design one upcoming audit with the four stages. Write where you will sit, whom you will observe, what open questions you will ask, and what decision you hope will come out.”

— Try it now

What do you take with you?

  • The organised illusion is complete documents and absent truth. Its worst feature is that it carries a stamp reading “sound”.
  • Every organisation holds two kinds of work: as imagined and as done. The gap between them is natural; its problem is that audit does not see it.
  • High compliance can be a shield that hides risk. Modern standards ask for proof of effectiveness, not of existence.
  • A process visit takes the auditor to the floor and treats deviation as a signal, not a violation.
  • Four stages: observation, gap analysis, operational interpretation, and linking to improvement. Three paths: design, enablement and exception.

We usually begin by asking: is the procedure documented? The better questions are: does it work, and are we ready to see what actually happens? Whoever decides to see himself honestly lays the foundation of a culture that does not fear the truth but builds on it.

At RAISO we work with organisations on designing process visits, training auditors in reality-based audit, and linking its outputs to improvement initiatives. If you have an audit coming up, we suggest adding to it this week one field visit before any review of files. To go deeper, explore RAISO’s procedures management and audit practice, or write to us at marhaba@raiso.sa.

“The case, names and numbers in this article are hypothetical, for illustration only, and do not refer to any particular organisation.”

— Note